AWS Solution
Enterprise Auditor for AWS helps organizations secure data stored in the Amazon Web Services (AWS) S3 platform. It reduces risk exposure through proactive, automated auditing and reporting of S3 permissions and sensitive data, giving you a consolidated view of user access rights across dozens of structured and unstructured data resources both on-premises and in the cloud.
The AWS Solution is designed to provide information about data access such as:
- Who has access to your data
- Who is accessing your data
- What sensitive data is being stored and accessed
The AWS Solution lets you audit AWS IAM and S3. Enterprise Auditor uses the AWS solution to collect IAM users, groups, roles, and policies, as well as S3 permissions, content, and sensitive data from target AWS accounts. The solution requires a special Enterprise Auditor license. You can focus it to audit only AWS IAM. Additionally, the Sensitive Data Discovery Add-On enables the solution to search AWS S3 content for sensitive data.
Supported Platforms
- Amazon AWS IAM
- Amazon AWS S3
Requirements, Permissions, and Ports
See the Target Amazon Web Service Requirements, Permissions, and Ports topic for additional information.
Sensitive Data Discovery Considerations
The Sensitive Data Discovery Add-On must be installed on the Enterprise Auditor Console server, which enables Sensitive Data criteria for scans. If you run Sensitive Data Discovery (SDD) scans, increase the minimum amount of RAM. Each thread requires a minimum of 2 additional GB of RAM per host. For example, if you configure the job to scan 8 hosts at a time, it requires an extra 16 GB of RAM (8 x 2 = 16).
The Sensitive Data Discovery Add-on installation package installs the appropriate Java Development Kit (JDK) version on the server. The deployed JDK is prepackaged and doesn't require any configuration; it comes preconfigured to work with Enterprise Auditor. Don't customize it through Java. It won't conflict with other JDKs or Java Runtimes in the same environment.
Location
The AWS Solution requires a special Enterprise Auditor license. It can be installed from the Enterprise Auditor Instant Job Wizard. See the Instant Job Wizard topic for information on installing instant solutions from the Enterprise Auditor Library.
After it has been installed into the Jobs tree, navigate to the solution: Jobs > AWS.
Job Groups
The AWS solution is a comprehensive set of pre-configured audit jobs and reports that provide visibility into IAM users, groups, roles, and policies, as well as S3 permissions, content, and sensitive data from target AWS accounts.

The AWS Solution is comprised of the following job groups:
- 0.Collection Job Group – The 0.Collection Job Group scans and collects details on IAM and S3 buckets within an AWS organization
- 1.Organizations Job Group – The 1.Organizations Job Group provides details on AWS accounts and users
- 2.Users Job Group – The 2.Users Job Group provides details on AWS IAM user MFA status, access key usage, and staleness
- 3.Groups Job Group – The 3.Groups Job Group provides details on AWS IAM group membership, orphaned groups (those with no policy assigned to them), sensitive security group membership, and stale groups
- 4.Roles Job Group – The 4.Roles Job Group provides details on roles in the AWS IAM environment
- 5.Policies Job Group – The 5.Policies Job Group provides details on AWS IAM policies including the various types of policies, the permissions they grant, and where they are applied in the AWS organization
- 6.S3 Permissions Job Group – The 6.S3 Permissions Job Group provides details on permissions assigned to AWS S3 buckets, highlighting specific threats like broken inheritance and open buckets
- 7.S3 Content Job Group – The 7.S3 Content Job Group provide details on AWS S3 buckets and objects contained in those buckets
- 8.S3 Sensitive Data Job Group – The 8.S3 Sensitive Data Job Group provides details on AWS S3 buckets and objects containing sensitive data